CVE-2026-34205Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration does not restrict access to the app as intended, allowing any device on the same network to reach these endpoints without authentication. Home Assistant Supervisor 2026.03.02 addresses the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-923

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-27); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Mentions · 2026-04-02: 1Mentions · 2026-06-19: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 2Technical Details · 2026-06-19: 103-2703-2804-0206-19
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-273
Disclosure1General1Patch1
2026-03-281
General1
2026-04-021
Disclosure1
2026-06-191
Disclosure1
Full discourse6 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Home Assistant, Unauthenticated Information Disclosure, #CVE-2026-34205 (Critical) -DC-Jun2026-495 https://dailycve.com/home-assistant-unauthenticated-information-disclosure-cve-2026-34205-critical-dc-jun2026-495/

    Post summary

    The text links to a DailyCVE article announcing a critical unauthenticated information disclosure in Home Assistant (CVE-2026-34205). No PoC, exploit code, patch, or active exploitation details are provided in the snippet.

    0000034
    213 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-34205: Home Assistant Internal Docker Bridge Bug - What It Means for Your Business and How to Respond https://hubs.li/Q049rNHF0

    Post summary

    The text points to a new Home Assistant CVE but offers only a headline and link without concrete technical details, PoC, exploitation, or patch information.

    0000030
    31 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34205 Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network … https://www.cve.org/CVERecord?id=CVE-2026-34205

    Post summary

    The post merely cites the CVE record for CVE-2026-34205 in Home Assistant without providing any specific exploit information, technical details, or mitigation guidance.

    00000137
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-34205 - Critical Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthent... https://www.thehackerwire.com/vulnerability/CVE-2026-34205/ https://t.co/vVFuo5qxxo

    Post summary

    The tweet alerts to CVE‑2026‑34205—a critical flaw in Home Assistant apps using host network mode—but supplies no evidence of an exploit, PoC, active attacks, or mitigation.

    0000049
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34205: CRITICAL] Home Assistant Supervisor 2026.03.02 fixes security flaw enabling unauthorized access to unauthenticated endpoints on the local network. Keep your systems updated for enhanced cybe...#cve,CVE-2026-34205,#cybersecurity https://cvefind.com/CVE-2026-34205

    Post summary

    The post announces an update that patches CVE-2026‑34205, highlighting the fix for unauthorized access to unauthenticated local network endpoints, and urges users to apply the update.

    0000057
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34205: Home Assistant: Unauthenticated ... Docker bridge misconfiguration turns every Home Assistant add-on into a network-wide RCE vector - 9.7 CVSS speaks volum... https://zerodaysignal.com/vulnerability/CVE-2026-34205 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-34205, noting that a Docker bridge misconfiguration makes Home Assistant add‑ons vulnerable to remote code execution with a high CVSS score of 9.7, but lacks evidence of PoC, active exploitation, or patches.

    0000065
    194 followersView on X

Explore more